CVE-2026-49270
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
In short
Apache ActiveMQ brokers with network connectors can leak sensitive subscription information to unauthenticated attackers. An attacker can obtain details about durable topic subscriptions, client IDs, and filtering rules without logging in.
Technical detail
An unauthenticated attacker can send a crafted BrokerInfo command via OpenWire protocol to brokers configured with syncDurableSubs=true, exploiting missing authentication checks to enumerate all durable subscription metadata including client identifiers, subscription names, destinations, and JMS selector expressions. The vulnerability affects ActiveMQ versions before 5.19.7 and 6.0.0-6.2.5, and requires the broker to have network connectors enabled.
Summary generated and translated by AI from the official description.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Apache Software Foundation · Apache ActiveMQApache Software Foundation · Apache ActiveMQ AllApache Software Foundation · Apache ActiveMQ BrokerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →